Please let me know the correct data extraction?
index=* "Unknown message for StatusConsumer" topicId marshall
| rex field=_raw "\"topicId\":\"(?<topicId>\d+)\""
| table topicId
Datas are not getting parsed after giving table name on splunk query.
regex was not applied correctly thats why it was not extracting the data.
Thank you
Please post an example of your data containing topicid
Hi @Splunk-Star,
After using table or stats commands Splunk shows only outputs of these commands. This does not mean they are not extracted. If you need to access other fields, add them to the table command.